cbcvebase.
CVE-2023-40338
published 2023-08-16

CVE-2023-40338: Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system.

Affected

15 ranges
VendorProductVersion rangeFixed in
jenkinsblue_ocean_plugin
jenkinsconfig_file_provider_plugin
jenkinsdelphix_plugin
jenkinsdocker_swarm_plugin
jenkinsfavorite_view_plugin
jenkinsflaky_test_handler_plugin
jenkinsfolders<= 6.846.v23698686f0f6
jenkinsfolders_plugin
jenkinsfortify_plugin
jenkinsgogs_plugin
jenkinsimproper_masking_of_credentials_in_nodejs_plugin
jenkinsnodejs_plugin
jenkinsshortcut_job_plugin
jenkinstuleap_authentication_plugin
jenkins_projectjenkins_folders_plugin<= 6.846.v23698686f0f6